7 ms·
I used to be a pentester, so it was pretty applicable... Pentesting really requires "full stack" systems knowledge, from networking, to OS, to API analysis, ma
by robcohen 4y ago
I used to be a pentester, so it was pretty applicable...
Pentesting really requires "full stack" systems knowledge, from networking, to OS, to API analysis, malware analysis, binary reverse engineering. OSCP is an applied cert, so it really forces you to be able to leverage knowledge in a practical way.
However my favorite benefit of offsec is really being able to see things from an attacker's perspective. This has been super valuable in many situations and I've found I'm many times the only person in the room with an awareness of an adversarial mindset.
- meristem 4y agoIt does make risk analysis more interesting. It surprises me how people will think only of the positive or accidental case, leaving adversarial ones off the table (and risk mitigation)
- markoman 4y agoI'm thinking about getting into pen-testing and eventually getting an OSCP. Would you mind offering a few words about why you left the pen-testing field? Also, do you have a CEH or do you recommend bypassing it in favor of the OSCP?
- robcohen 4y agoCEH is literally useless, I used to have it because I did DoD. That’s the only reason to do it. I got out of pentesting because no one follows your recommendations. I could give 40 recommendations after doing a pentest, come back a year later and none of them would have been implemented. People don’t care about security—-it’s why everything is broken and it’s getting worse. I moved into Distributed Ledger Technology because I think it could help solve security issues people face daily in a way where they cannot mess up. That’s the idea anyway.